11

NameCheap's email hacked to send Metamask, DHL phishing emails

 1 year ago
source link: https://www.bleepingcomputer.com/news/security/namecheaps-email-hacked-to-send-metamask-dhl-phishing-emails/
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

NameCheap's email hacked to send Metamask, DHL phishing emails

  • February 12, 2023
  • 06:07 PM
  • 1
Phishing emails

Domain registrar Namecheap had their email account breached Sunday night, causing a flood of MetaMask and DHL phishing emails that attempted to steal recipients' personal information and cryptocurrency wallets.

The phishing campaigns started around 4:30 PM ET and originated from SendGrid, an email platform used historically by Namecheap to send renewal notices and marketing emails.

After recipients began complaining on Twitter, Namecheap CEO Richard Kirkendall confirmed that the account was compromised and that they disabled email through SendGrid while they investigated the issue.

Kirkendall also said that they believe the breach may be related to a December CloudSek report on the API keys of Mailgun, MailChimp, and SendGrid being exposed in mobile apps.

A flood of emails

The phishing emails sent in this campaign are impersonating either DHL or MetaMask.

The DHL phishing email pretends to be a bill for a delivery fee required to complete the delivery of a package. While BleepingComputer has not received this email, we were told that the embedded links lead to a phishing page attempting to steal the target's information.

BleepingComputer did receive the MetaMask phishing email, which pretends to be a required KYC (Know Your Customer) verification to prevent the wallet from being suspended.

MetaMask phishing email from Namecheap
MetaMask phishing email from Namecheap
Source: BleepingComputer.com

"We are writing to inform you that in order to continue using our wallet service, it is important to obtain KYC (Know Your Customer) verification. KYC verification helps us to ensure that we are providing our services to legitimate customers," reads the MetaMask phishing email.

"By completing KYC verification, you will be able to securely store, withdraw, and transfer funds without any interruptions. It also helps us to protect you against financial fraud and other security threats."

"We urge you to complete KYC verification as soon as possible to avoid suspension of your wallet."

This email contains a marketing link from Namecheap (https://links.namecheap.com/) that redirects the user to a phishing page pretending to be MetaMask.

This page prompts the user to enter their 'Secret Recovery Phrase' or 'Private key,' as shown below.

metamask-phishing-page.jpg
MetaMask phishing page
Source: BleepingComputer

Once a user provides either the recovery phrase or private key, the threat actors can use them to import the wallet to their own devices and steal all the funds and assets.

If you received either a DHL or MetaMask phishing email tonight from Namecheap, immediately delete it and do not click on any links.

BleepingComputer contacted Twilio about this breach and was told their systems were not hacked or breached. 

The full statement from Twilio is below:

“Twilio SendGrid takes fraud and abuse very seriously and invests heavily in technology and people focused on combating fraudulent and illegal communications. We are aware of the situation regarding the use of our platform to launch phishing email and our fraud, compliance and cyber security teams are engaged in the matter. This situation is not the result of a hack or compromise of Twilio’s network. We encourage all end users and entities to take a multi-pronged approach to combat phishing attacks, deploying security precautions such as two factor authentication, IP access management, and using domain-based messaging. We are still investigating the situation and have no additional information to provide at this time.” Twilio Corp.

BleepingComputer also contacted Namecheap, but a response was not immediately available.


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK